cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
506
Views
0
Helpful
4
Replies

how exclude subnet/ip from Accounting in AAA ????

Dr.X
Level 2
Level 2

Hi , 

 i have router 7206 as LNS with radius for AAA .

all things works fine .

but i have some free services that im gonna produce for my clients and i dont want these services traffic to be counted in the accounting .

is there is a way to stop that accounting traffic from being sent for specific subnet or ip  ?? or at least i distinguish it to radius server .

again i have Cisco 7206 router.

Lns2#sh version
Cisco IOS Software, 7200 Software (C7200P-ADVENTERPRISEK9-M), Version 12.4(24)T8, RELEASE SOFTWARE (fc1)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2012 by Cisco Systems, Inc.
Compiled Sun 09-Sep-12 07:00 by prod_rel_team

ROM: System Bootstrap, Version 12.4(12.2r)T, RELEASE SOFTWARE (fc1)
BOOTLDR: Cisco IOS Software, 7200 Software (C7200-KBOOT-M), Version 12.4(4)XD, RELEASE SOFTWARE (fc1)

Bras2 uptime is 7 weeks, 1 day, 14 hours, 10 minutes
System returned to ROM by reload at 08:28:02 GMT+3 Tue Jun 22 2004
System image file is "disk2:c7200p-adventerprisek9-mz.124-24.T8.bin"
Last reload reason: Reload Command

This product contains cryptographic features and is subject to United
States and local country laws governing import, export, transfer and
use. Delivery of Cisco cryptographic products does not imply
third-party authority to import, export, distribute or use encryption.
Importers, exporters, distributors and users are responsible for
compliance with U.S. and local country laws. By using this product you
agree to comply with applicable laws and regulations. If you are unable
to comply with U.S. and local laws, return this product immediately.

A summary of U.S. laws governing Cisco cryptographic products may be found at:
http://www.cisco.com/wwl/export/crypto/tool/stqrg.html

If you require further assistance please contact us by sending email to
export@cisco.com.

Cisco 7206VXR (NPE-G2) processor (revision A) with 917504K/65536K bytes of memory.
Processor board ID 26790100
MPC7448 CPU at 1666Mhz, Implementation 0, Rev 2.2
6 slot VXR midplane, Version 2.9

Last reset from power-on

PCI bus mb1 (Slots 1, 3 and 5) has a capacity of 600 bandwidth points.
Current configuration on bus mb1 has a total of 0 bandwidth points.
This configuration is within the PCI bus capacity and is supported.

PCI bus mb2 (Slots 2, 4 and 6) has a capacity of 600 bandwidth points.
Current configuration on bus mb2 has a total of 0 bandwidth points.
This configuration is within the PCI bus capacity and is supported.

Please refer to the following document "Cisco 7200 Series Port Adaptor
Hardware Configuration Guidelines" on Cisco.com <http://www.cisco.com>
for c7200 bandwidth points oversubscription and usage guidelines.


1 FastEthernet interface
3 Gigabit Ethernet interfaces
2045K bytes of NVRAM.

254464K bytes of ATA PCMCIA card at slot 2 (Sector size 512 bytes).
65536K bytes of Flash internal SIMM (Sector size 512K).
Configuration register is 0x2102

cheers

1 Accepted Solution

Accepted Solutions

It wont make much difference.  Netflow just spits out flows.  You would need to tie these back to users based on the IP address, and exclude the flows that you want to be free.

View solution in original post

4 Replies 4

Philip D'Ath
VIP Alumni
VIP Alumni

How are the user connections presented?   Virtual-Access interfaces?  If so then I don't think so.  aaa accounting is not aware of packet contents in this scenario, just the packet sizes.

A huge change, but could you use netflow accounting instead?  That is IP aware and has the source and destination IP addresses.  You can also choose to put all the free services on one interface and not apply netflow accounting to it.  Or you can simply filter out the IP addresses/subnets you want to be free.

yes , correct , all the sessions are under the interfaces "virtual-access"

also , about the ip netflow accounting , i dont have the traffic that im  interested to be filtered out of accounting on the same router interface , but its  on remote server and all the traffic comes into 1 lan interface

so im wondering f that is possible or not

my kind regards

It wont make much difference.  Netflow just spits out flows.  You would need to tie these back to users based on the IP address, and exclude the flows that you want to be free.

dear philip  ,

could you help me with the needed settings that are needed to be put int he radius & cisco Nas router ?

my kind regards

Review Cisco Networking products for a $25 gift card